Skip to main content

Company intelligence

Surveymonkey cybersecurity incidents and threat signals

surveymonkey.com

Surveymonkey logo

This company page brings together public reporting currently associated with Surveymonkey. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

1

Last 28 days

recent published signals

1

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 28, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Surveymonkey. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Surveymonkey

Surveymonkey logoInfostealer
High

SurveyMonkey Experiences Significant Credential Exposure Affecting Nearly One Million Clients and Over 8,000 Employees

SurveyMonkey, a U.S.-based software company providing online survey and feedback tools, has been identified in a significant credential exposure event with a high-risk score. The incident involves 853,111 historical data breaches and 124,422 active infostealer logs, impacting approximately 969,240 clients and 8,293 employees. The exposure is primarily linked to "Combolist sources" (99.6%) and "Database dumps" (0.4%) within leak repositories, indicating that compromised credentials are the main vector. Malware families such as Redline, LummaC2, and Rhadamanthys are prevalent, suggesting active credential harvesting and data exfiltration. The infostealer malware primarily targets Windows 10 and Windows 11 operating systems, with a notable presence in India, Brazil, and the United States. This event highlights the urgent need for credential resets and enhanced monitoring for unusual access patterns. SurveyMonkey's security statement, updated in November 2025, outlines its commitment to data protection, including AES 256 encryption for data at rest and RSA encryption for data in motion, as well as ISO 27001 certification and a vulnerability management program. However, the current exposure indicates a persistent threat despite these measures. The company's privacy notice, effective May 2026, details the types of personal data collected and how it is shared, emphasizing that data is not shared with third parties outside SurveyMonkey except in limited circumstances, such as with administrators in enterprise plans or in response to legal requests. The notice also mentions the use of event data to investigate security issues and prevent unlawful activities. The incident underscores the ongoing challenges organizations face in protecting against sophisticated credential-stealing malware and the importance of robust authentication mechanisms and user education.

Surveymonkey

FAQ

Questions about Surveymonkey cybersecurity reporting

What does the Surveymonkey page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Surveymonkey.

Does every mention of Surveymonkey appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.